QID 198754

Date Published: 2022-04-28

QID 198754: Ubuntu Security Notification for libsepol Vulnerabilities (USN-5391-1)

Libsepol incorrectly handled memorywhen handling policies.
Libsepol incorrectly handled memory whenhandling policies.
Libsepol incorrectly handled memory whenhandling policies.
Libsepol incorrectly validated certain data,leading to a heap overflow.

An attacker could possibly use this issueto cause a crash, resulting in a denial of service, or possiblyexecute arbitrary code.
An attacker could possibly use this issue to causea crash, resulting in a denial of service, or possibly executearbitrary code.
An attacker could possibly use this issue to causea crash, resulting in a denial of service, or possibly executearbitrary code.
An attacker could possibly use this issueto cause a crash, resulting in a denial of service, or possibly executearbitrary code.

  • CVSS V3 rated as Medium - 3.3 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5391-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198754

    Software Advisories
    Advisory ID Software Component Link
    USN-5391-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5391-1